CVE-2012-3569

VMware OVF Tool 2.1 - Remote Code Execution via Crafted OVF File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2012-3569. PoCs published by Metasploit, Jeremy Brown, juan vazquez, including Metasploit module exploits/windows/browser/ovftool_format_string.

AI-analyzed exploit summary This Metasploit module exploits a format string vulnerability in VMWare OVF Tools 2.1 for Windows. It crafts a malicious OVF file that triggers the vulnerability when parsed, leading to arbitrary code execution.

Description

Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/24461

This Metasploit module exploits a format string vulnerability in VMWare OVF Tools 2.1 for Windows. It crafts a malicious OVF file that triggers the vulnerability when parsed, leading to arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMWare OVF Tools 2.1
No auth needed
Prerequisites: VMWare OVF Tools 2.1 installed on Windows XP SP3
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/24460

This Metasploit module exploits a format string vulnerability in VMWare OVF Tools 2.1 for Windows. It crafts a malicious OVF file to achieve remote code execution by leveraging a format string attack during error message parsing.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMWare OVF Tools 2.1 on Windows XP SP3
No auth needed
Prerequisites: Network access to the target system · Target system running VMWare OVF Tools 2.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Jeremy Brown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ovftool_format_string.rb

This Metasploit module exploits a format string vulnerability in VMWare OVF Tools 2.1 for Windows. It crafts a malicious OVF file with a format string payload to achieve remote code execution by overwriting the saved EBP and redirecting execution flow.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMWare OVF Tools 2.1 on Windows XP SP3
No auth needed
Prerequisites: Target must be running VMWare OVF Tools 2.1 on Windows XP SP3 · Attacker must be able to serve a malicious OVF file to the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Jeremy Brown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ovf_format_string.rb

This Metasploit module exploits a format string vulnerability in VMWare OVF Tools 2.1 for Windows. It crafts a malicious OVF file that triggers the vulnerability when parsed, leading to arbitrary code execution via a controlled format string attack.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMWare OVF Tools 2.1 on Windows XP SP3
No auth needed
Prerequisites: VMWare OVF Tools 2.1 installed on target system · Ability to deliver malicious OVF file to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/79922
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2012-0015.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87117
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51240

Scores

EPSS 0.4772
EPSS Percentile 98.7%

Details

CWE
CWE-134
Status published
Products (14)
vmware/ovf_tool 2.1
vmware/player 4.0
vmware/player 4.0.0.18997
vmware/player 4.0.1
vmware/player 4.0.2
vmware/player 4.0.3
vmware/player 4.0.4
vmware/workstation 8.0
vmware/workstation 8.0.0.18997
vmware/workstation 8.0.1
... and 4 more
Published Nov 14, 2012
Tracked Since Feb 18, 2026